QID 379340
Date Published: 2024-02-06
QID 379340: HashiCorp Vault Sensitive Information Disclosure Vulnerability (HCSEC-2024-01)
Vault is a tool for securely accessing secrets. A secret is anything that you want to tightly control access to, such as API keys, passwords, or certificates. Vault provides a unified interface to any secret while providing tight access control and recording a detailed audit log.
CVE-2024-0831: Vault and Vault Enterprise may expose sensitive information when enabling an audit device which specifies the log_raw option, which may log sensitive information to other audit devices, regardless of whether they are configured to use log_raw.
Affected version(s):
HashiCorp Vault and Vault Enterprise 1.15.0 through 1.15.4
QID Detection Logic(Authenticated):
Linux: This QID fires vault --version command to detect the vulnerable version of Vault.
Successful exploitation of these vulnerabilities could leak sensitive information protected by vault encryption.
CVEs related to QID 379340
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| HCSEC-2024-01 |
|